Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

ServiceNow

First CVE: Mar 15, 2018Active for: 8 yearsTotal CVEs: 18
56.4
VTI Score
TOP TARGET

ServiceNow is a prominent enterprise workflow and IT service management platform with a focused product portfolio spanning its core service-management suite, AI agent extensions, and API-driven integrations that serve as operational backbone systems for many organizations. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated tendency toward confirmed in-the-wild exploitation and widespread public exploit availability, reflecting the platform's role as a high-value target and its exposure through web-tier and API attack surfaces. The recurring exposure concentrates in weakness classes including cross-site scripting, code injection, unnecessary privilege execution, and information disclosure, which are characteristic of large, multi-tenant application platforms handling sensitive business logic and access controls. Defenders should prioritize ServiceNow advisories and treat the platform as a critical patching target given its breadth of integration and administrative reach; current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
18
Total CVEs
More Total CVEs than 95% of tracked vendors
0.8
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 10% of tracked vendors
7.0
Avg CVSS Score
Higher Avg CVSS Score than 49% of tracked vendors
11.1%
In CISA KEV
Higher KEV Rate than 100% of tracked vendors

Trends Over Time

The number and severity of CVEs published that impact products developed by ServiceNow over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 15, 2018
8 years ago
Most Recent CVE
Jan 12, 2026
194 days ago

Self-Reporting Analysis

Of all the CVEs published by ServiceNow as a CNA, 50.0% affect products that ServiceNow develops as a vendor.

50.0%
50.0%
Self-reported: 11 (50.0%)
Third-party: 11 (50.0%)

Of all the CVEs published that affect products developed by ServiceNow, 61.1% are self-published by ServiceNow as a CNA.

61.1%
38.9%
Self-published: 11 (61.1%)
Other CNAs: 7 (38.9%)

Products(4 total)

Top CVEs

Signals from CVEs in this vendor scope (18 CVEs).

18 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2024-5217CRITICAL
ServiceNow has addressed an input validation vulnerability that was identified in the Washington DC, Vancouver, and earlier Now Platform releases. This vulnerability could enable a
Jul 10, 20249.898YESYES
CVE-2024-4879CRITICAL
ServiceNow has addressed an input validation vulnerability that was identified in Vancouver and Washington DC Now Platform releases. This vulnerability could enable an unauthentica
Jul 10, 20249.898YESYES
CVE-2025-12420CRITICAL
A vulnerability has been identified in the ServiceNow AI Platform that could enable an unauthenticated user to impersonate another user and perform the operations that the imperson
Jan 12, 20269.861NONO
CVE-2022-38463MEDIUM
ServiceNow through San Diego Patch 4b and Patch 6 allows reflected XSS in the logout functionality.
Aug 23, 20226.132NOYES
CVE-2024-8923CRITICAL
ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code
Oct 29, 202410.031NONO
CVE-2022-39048MEDIUM
A XSS vulnerability was identified in the ServiceNow UI page assessment_redirect. To exploit this vulnerability, an attacker would need to persuade an authenticated user to click a
Apr 10, 20236.131NOYES
CVE-2021-45901MEDIUM
The password-reset form in ServiceNow Orlando provides different responses to invalid authentication attempts depending on whether the username exists.
Feb 10, 20225.329NOYES
CVE-2018-7748HIGH
report_viewer.do in ServiceNow Release Jakarta Patch 8 and earlier allows remote attackers to execute arbitrary code via '${xyz}' Glide Scripting Injection in the sysparm_media par
Aug 3, 20188.828NONO
CVE-2024-8924HIGH
ServiceNow has addressed a blind SQL injection vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to extract unauthorize
Oct 29, 20247.524NONO
CVE-2022-43684MEDIUM
ServiceNow has released patches and an upgrade that address an Access Control List (ACL) bypass issue in ServiceNow Core functionality. Additional Details This issue is present
Jun 13, 20236.522NONO
View all 18 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products18 CVEs
67%
11%
22%
Severity distribution among all CVEs352,708 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network18 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low18 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None8 (44.4%)
Unknown0 (0.0%)
Required10 (55.6%)
Privileges Required
Low6 (33.3%)
High0 (0.0%)
None12 (66.7%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (18 CVEs).

CISA KEV
2 CVEs
11.1% of CVEs· 100th percentile
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
4 CVEs
22.2% of CVEs· 97th percentile
ExploitDB
2 CVEs
11.1% of CVEs· 76th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by ServiceNow.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by ServiceNow — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For ServiceNow's Products

View all 2 CNAs →

Top CWEs